Integration · SIEM

HailBytes + Microsoft Sentinel

External exposure and phishing-simulation telemetry landing in the same workspace as the rest of your Microsoft security estate.

What you get

  • Native Log Analytics ingestion. Findings and campaign events write into your Azure Log Analytics workspace, so they're queryable in KQL alongside Defender, Entra sign-in, and Azure activity data.
  • Full context on every record. Findings arrive with the asset, severity, discovery source, and evidence attached — enough to write a detection rule against, not just enough to display.
  • Severity floor + category toggles. Control which severities and event categories (vulnerability, scan, audit, change, brand-risk) reach the workspace on a per-project basis, so ingestion cost stays predictable.
  • Deterministic dedup. A finding rediscovered on the next scan cycle updates rather than duplicating, so correlation rules don't fire repeatedly on the same exposure.

Bring your own workspace ID and key. The connection runs from your single-tenant HailBytes instance directly to your workspace, and Log Analytics ingestion stays on your existing Azure subscription — counting toward MACC commitments like the rest of your Azure spend.

HailBytes is also listed on Azure Marketplace, so both products can be deployed and billed through the same Microsoft agreement.

SIEM setup guide → Azure Marketplace → All integrations →